Earlier quoted context omitted.
You're right; that's what ATO means here.
Same difference. Anti account take over and account authentication, because similar methods would be deployed (i.e., multifactor authentication, heuristic, etc.)
“We found PayPal vulnerabilities and PayPal punished us for it”
301–310 of 337 posts
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#302Earlier quoted context omitted.
My experience with PayPal, from dev support to account managers, has been an absolute shit show. They were simply the first to their market and it's hard to kick them out.
It was difficult at first, this happened quite some time ago, but these days it seems there are lots of non-paypal options.
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#303People have a weird mental model of how big-company bug bounty programs work. Paypal --- a big company for sure, with a large and talented application security team --- is not interested in stiffing researchers out of bounties. They have literally no incentive to do so. In fact: the people tasked with running the bounty probably have the opposite incentive: the program looks better when it is paying out bounties for…
Really? Most companies? That seems like an extraordinary claim.
I'm not a security researcher but if I stumbled on some security issue in something that's not open-source and not owned by my employer, the only way I'd consider reporting it is if they have a bug bounty / responsible disclosure program. Otherwise I'd expect it would be about as likely for me to receive a "thank you" as a knock on the door from law enforcement.
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#304Earlier quoted context omitted.
It presumes a definition of "responsible" that suits the interests of vendors and treats the safety of end-users as an externality, in such a way that anyone operating in good faith and responding to different legitimate incentives is by definition "not" disclosing "responsibly". It's a linguistic ploy, and not one that should be dignified. In 2020, non-ironic use of the term "responsible disclosure" has become somew…
That sort of makes sense, but what are examples of other legitimate incentives that might compel a researcher to disclose the presence of a vulnerability before the vendor has a fix?
Otherwise, research suggests that the chances of a vulnerability being independently rediscovered within three months may be as high as 1 in 5 for certain types of defects[1]. This means that even if you don’t know a particular vulnerability is being actively exploited, you’ll eventually find one that’s being quietly exploited by someone. Since you don’t know which one it’ll be, early disclosure at least gives end users the opportunity to apply mitigations and hopefully burns a 0-day being used by an internet bad guy.
[0] https://googleprojectzero.blogspot.com/p/vulnerability-discl... - “Why are disclosure deadlines necessary?”
[1] https://papers.ssrn.com/sol3/papers.cfm?abstract_id=2928758
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#305Earlier quoted context omitted.
Help me out here, in what way is it Orwellian? I always assumed the responsible part had multiple non-conflicting meanings, that 1) The researcher would not disclose it to the public until the vendor has a reasonable amount of time to fix it and 2) the vendor is assumed to want to do the right and responsible thing in fixing the flaw.
It presumes a definition of "responsible" that suits the interests of vendors and treats the safety of end-users as an externality, in such a way that anyone operating in good faith and responding to different legitimate incentives is by definition "not" disclosing "responsibly". It's a linguistic ploy, and not one that should be dignified. In 2020, non-ironic use of the term "responsible disclosure" has become somew…
So, what is the correct term that is supposed to be applied to the approach of disclosing to a vendor first, giving them a hard deadline, and then doing a public disclosure? As far as I know, it’s not “coordinated disclosure”, since “coordinated disclosure” normally means the vendor controls the timeline.
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#306HackerOne is complete garbage. I spent close to a month digging into Uber and compromised their m.uber.com mobile endpoint; they hemmed and hawed and then awarded the $25K to another HackerOne top performer stating that he had discovered the exact same vulnerability the day before I had submitted the report. What's weird about it is that I was using Burp Proxy for everything, and this guy was directly connected to Po…
Hi, I work at PortSwigger. > Uber was running some promotional for a free three month license for Burp Proxy This is flat out wrong - the promotional partnership was done with HackerOne. > What's weird about it is that I was using Burp Proxy for everything... Burp Suite is used by tens of thousands of security experts and if we posted vulnerability data back we would get caught in about ten seconds. Also it would be…
I wrote it all up on Medium, it got close to 400K reads over the 2018 Christmas holiday with many other stories in a similar vein related to incompetence in their security group. HackerOne is worthless, a scam unless you are full time working for them on bug bounties and already connected with their top ranked researchers.
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#307Earlier quoted context omitted.
You put in way too much effort. Call your credit card company first. Your credit card company profits from vendor (PayPal) mistakes by charging fees, so they are always happy to help you.
calling the Card issuer is always my first stop. CS these days is abysmal at most companies.
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#308HackerOne is complete garbage. I spent close to a month digging into Uber and compromised their m.uber.com mobile endpoint; they hemmed and hawed and then awarded the $25K to another HackerOne top performer stating that he had discovered the exact same vulnerability the day before I had submitted the report. What's weird about it is that I was using Burp Proxy for everything, and this guy was directly connected to Po…
Hi, I work at PortSwigger. > Uber was running some promotional for a free three month license for Burp Proxy This is flat out wrong - the promotional partnership was done with HackerOne. > What's weird about it is that I was using Burp Proxy for everything... Burp Suite is used by tens of thousands of security experts and if we posted vulnerability data back we would get caught in about ten seconds. Also it would be…
These were three critical vulnerabilities on the m.uber.com endpoint; I was able to bypass their WAF and XSS_Auditor protections followed by demonstrating reflected SSL'ized XSS under *.uber.com certificate and remote javascript execution capability.
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#309HackerOne is complete garbage. I spent close to a month digging into Uber and compromised their m.uber.com mobile endpoint; they hemmed and hawed and then awarded the $25K to another HackerOne top performer stating that he had discovered the exact same vulnerability the day before I had submitted the report. What's weird about it is that I was using Burp Proxy for everything, and this guy was directly connected to Po…
Hi, I work at PortSwigger. > Uber was running some promotional for a free three month license for Burp Proxy This is flat out wrong - the promotional partnership was done with HackerOne. > What's weird about it is that I was using Burp Proxy for everything... Burp Suite is used by tens of thousands of security experts and if we posted vulnerability data back we would get caught in about ten seconds. Also it would be…
Which would be trivial to implement as a covert channel in Burp Proxy's update process or any one of another methods of obfuscating and tunneling that data back to Portswigger.
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#310HackerOne is complete garbage. I spent close to a month digging into Uber and compromised their m.uber.com mobile endpoint; they hemmed and hawed and then awarded the $25K to another HackerOne top performer stating that he had discovered the exact same vulnerability the day before I had submitted the report. What's weird about it is that I was using Burp Proxy for everything, and this guy was directly connected to Po…
What would you expect HackerOne to do in the situation you describe? You filed a duplicate report. All of the malfeasance you allege is coming from Portswigger.
24K for one bounty... or sell $299 licenses to nerds.. hmm, which one is more profitable...